AssetLab Privacy Policy: Collection, Use, Security & Rights
Your Privacy is Our Priority
We are committed to protecting your personal information and being transparent about how we collect, use, and safeguard your data in compliance with Canadian privacy laws.
All legal documents
- Version
- 3.5
- Effective
- March 23, 2026
- Last updated
- August 7, 2026
Legal Entity: AssetLab CMMS Software Inc., North Vancouver, British Columbia, Canada
Regulatory Alignment Notice: This Privacy Policy is designed to comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada's Anti-Spam Legislation (CASL).
Where applicable, AssetLab has incorporated privacy best practices and transparency standards inspired by other data protection frameworks, including the GDPR and CCPA/CPRA. These references apply only where legally required.
1. Introduction
1.1 Scope and Application
AssetLab CMMS Software Inc. ("AssetLab," "we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our asset management platform and services (the "Service").
This Privacy Policy applies to all users of AssetLab, including visitors to our website (assetlab.ca), registered users of the Service, and individuals whose information is processed through the Service. This Policy should be read in conjunction with our Terms of Service, which govern your use of the Service.
1.2 Data Controller and Data Processor Roles
For purposes of applicable data protection laws:
- AssetLab as Data Controller: For information we collect directly from you (account information, billing data, website usage), AssetLab acts as the "Data Controller" or "Business," determining the purposes and means of processing.
- AssetLab as Data Processor: For Customer Data you upload to the Service, AssetLab acts as a "Data Processor" or "Service Provider," processing personal information solely on your behalf and according to your instructions. In this role, you (our customer) are the Data Controller responsible for obtaining necessary consents and ensuring lawful processing.
This dual-role structure is further detailed in our Terms of Service (Section 8: Data Protection, Privacy, and Processing).
1.3 Consent and Acceptance
By accessing or using the Service, you consent to the collection, use, and disclosure of your information as described in this Privacy Policy. If you do not agree with our policies and practices, you must not access or use the Service.
Where we require your consent for specific processing activities (e.g., marketing communications, optional cookies), we will seek your explicit opt-in consent at the time of collection.
2. Information We Collect
We collect only the personal information that is necessary for the purposes identified in this Policy. We do not collect personal information indiscriminately.
We collect several types of information from and about users of our Service:
2.1 Personal Information
Personal information is data that can be used to identify you. We collect the following types of personal information:
- Account Information: Name, email address, phone number, job title, department, organization name
- Authentication Data: Email address for OTP (one-time password) and passkey authentication via Clerk
- Profile Information: User preferences, settings, and profile customization
- Communication Data: Information you provide when contacting our support team or communicating with us
2.2 Customer Data
Customer Data is information you input, upload, or create while using the Service, including:
- Asset information (descriptions, locations, specifications, serial numbers)
- Work order details and maintenance records
- Vendor and contractor information
- Parts inventory and procurement data
- Financial data related to asset management (costs, budgets, expenses)
- Documents, images, and attachments uploaded to the platform
- Any other business data you choose to store in the Service
Important: You retain all ownership rights to your Customer Data. We process Customer Data only as necessary to provide the Service and as instructed by you.
2.3 Automatically Collected Information
When you access or use the Service, we automatically collect certain technical information:
- Usage Data: Pages visited, features used, time spent on pages, click patterns
- Device Information: Device type, operating system, browser type and version
- Log Data: IP address, access times, error logs, performance data
- Cookies and Similar Technologies: Session identifiers, preferences, authentication tokens
2.4 Information from Third Parties
We may receive information about you from third-party services:
- Clerk: Authentication and identity verification data
- Analytics Services: Aggregated usage statistics and performance metrics
2.5 Mobile Applications
Our native iOS and Android applications do not contain an analytics SDK and do not collect Usage Data, cookies, or similar tracking technologies. The automatically collected information, cookies, and analytics practices described in Sections 2.3, 2.4, 3.4, 11.2, and 14 apply to our web-based Service, not to the mobile applications. The applications use the following device capabilities solely to provide features you initiate, with data stored only as part of the records you create:
- Camera: Used to scan QR codes and capture photos that you attach to work orders and assets. Images are stored only as work-order or asset content.
- Microphone and Speech Recognition: Used only when you start voice dictation. Both applications use the speech recognition built into the device operating system: on iOS, audio is sent to Apple for transient, on-the-fly transcription into text; on Android, the transcription is performed on the device and the audio is not transmitted to us or to a third party. In both cases we receive only the resulting text. No audio recording or voiceprint is created, stored, or retained by AssetLab. This is consistent with our prohibition on collecting biometric data, including voiceprints, described elsewhere in this Policy.
- Push Notifications: If you enable them, we use the Apple Push Notification service on iOS to deliver alerts about your work orders and assets. Push notifications are not currently offered in the Android application. You can disable notifications at any time in your device settings.
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Service Delivery
- Create and manage your account
- Authenticate your identity and maintain security
- Provide access to the Service and its features
- Process and store your Customer Data
- Deliver customer support and respond to inquiries
3.2 Billing and Payments
- Process subscription fees and payments
- Generate invoices and billing statements
- Manage subscription renewals and cancellations
- Detect and prevent payment fraud
3.3 Communication
- Send transactional emails (account notifications, password resets, billing confirmations)
- Provide customer support and technical assistance
- Send service announcements and updates (with opt-out option for non-essential communications)
- Respond to your requests, questions, and feedback
3.4 Service Improvement and Analytics
- Monitor and analyze usage patterns to improve the Service
- Develop new features and functionality
- Conduct research and analytics (using aggregated, anonymized data)
- Troubleshoot technical issues and optimize performance
3.5 Security and Compliance
- Detect, prevent, and respond to fraud, abuse, and security incidents
- Enforce our Terms of Service and other policies
- Comply with legal obligations and regulatory requirements
- Protect the rights, property, and safety of AssetLab, our users, and others
4. Legal Basis for Processing (PIPEDA Compliance)
Under PIPEDA, we process personal information based on the following legal grounds:
- Consent: You provide explicit or implied consent when creating an account and using the Service
- Contract Performance: Processing is necessary to fulfill our contractual obligations under the Terms of Service
- Legal Obligations: Processing is required to comply with Canadian laws and regulations
- Reasonable Purposes: Processing is necessary for purposes that a reasonable person would consider appropriate in the circumstances, including security, fraud prevention, and service improvement.
5. How We Share Your Information
We do not sell, rent, or trade your personal information. We may share your information in the following limited circumstances:
5.1 Service Providers (Subprocessors)
We engage trusted third-party service providers to assist in operating the Service. The current published Sub-processor List, including processing locations, the data each provider receives, and the safeguards in place, is maintained at assetlab.ca/trust.
- Clerk: Authoritative identity store and authentication (SOC 2 Type II certified; United States). Clerk holds the full identity record, including name, email, password hashes, MFA factors, session tokens, and SSO configuration
- Supabase: Database hosting, object storage, and Edge Functions (SOC 2 Type II certified; AWS Canada Central, Montreal). Supabase holds all Customer Data and a mirror of identity fields (Clerk user ID, name, business email, role) used for application joins and audit logging
- Cloudflare: Application delivery, web application firewall, DNS, and DDoS protection (SOC 2 Type II, ISO 27001; global edge). Transit traffic is decrypted at the edge for firewall inspection and is not stored; no persistent Customer Data
- Resend: Transactional email delivery for account, billing, and security notifications (United States). Notification emails carry the record title, organization name, and a link - never record content or attachments. Where you enable the optional email-to-work-request intake channel, Resend also receives the full content of inbound messages sent to your intake address
- Amazon Web Services: Offsite backup storage for the database, file storage, and identity export (Canadian data residency, AWS ca-central-1). Every archive is encrypted before it is uploaded using a key AWS does not hold, so the stored copies cannot be read by AWS
- Sentry: Application error monitoring and system diagnostics. Sentry receives diagnostic telemetry only - the exception message and stack trace, an opaque user identifier, and tenant, role, and component tags. It does not receive your name, email address, IP address, asset records, work orders, documents, or credentials
Our service providers are required to protect your information and use it only for the purposes we specify. Each is bound by a written data processing agreement with obligations no less protective than those in the AssetLab Data Processing Agreement, and AssetLab remains liable to you for their acts and omissions.
The public marketing site at www.assetlab.ca is hosted separately from the application and never receives Customer Data; its hosting provider is therefore not a subprocessor under this Policy. Third-party tools that you connect to AssetLab yourself - through the API, an MCP integration, or a webhook - are likewise not AssetLab subprocessors. You select, authorize, and control those connections and hold the relationship with the provider.
Device operating system services. On our mobile applications, push notifications are delivered through the notification service built into your device platform (the Apple Push Notification service on iOS), and voice dictation uses the speech recognition built into your device operating system - transient via Apple on iOS, and on-device on Android. These are platform services of the device you choose to use rather than service providers AssetLab engages, and they are not subprocessors under this Policy. Push notifications carry a record title and organization name only, and AssetLab does not store any audio or voiceprint. See Section 2.5 for the full mobile application disclosure.
5.2 Legal Requirements
We may disclose your information if required to do so by law or in response to:
- Valid legal processes (subpoenas, court orders, search warrants)
- Requests from government authorities or law enforcement
- Compliance with applicable laws and regulations
- Protection of our legal rights or those of others
5.3 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the successor entity. We will provide notice before your information is transferred and becomes subject to a different privacy policy.
5.4 With Your Consent
We may share your information for other purposes with your explicit consent.
6. Security of Your Information
We implement industry-standard security measures to protect your information:
6.1 Technical Safeguards
- Encryption: TLS 1.3 for data in transit, AES-256 for data at rest
- Authentication: Passwordless OTP and passkey authentication via Clerk with optional MFA
- Access Controls: Role-based access control (RBAC) with granular permissions
- Database Security: PostgreSQL row-level security (RLS) for multi-tenant data isolation
- Network Security: Firewalls, intrusion detection, and DDoS protection
Specific safeguards may evolve over time as security practices and technologies change.
6.2 Organizational Safeguards
- Regular security training for employees
- Strict internal access policies (need-to-know basis)
- Incident response and breach notification procedures
6.3 Security Limitations
While we implement strong security measures, no system is completely secure. We cannot guarantee absolute security of your information. You are responsible for maintaining the confidentiality of your account credentials and for any activities under your account.
6.4 Data Breach Notification and Incident Response
Data Breach Protocol: In the event of a security incident that results in unauthorized access to, disclosure of, or loss of personal information, AssetLab follows the notification protocol described below, consistent with PIPEDA, Quebec Law 25, and Section 8.4 of our Terms of Service.
Notification Timeline and Process
If we determine that a data breach has occurred that poses a real risk of significant harm to affected individuals, we will:
- Notify Our Customers (B2B): If Customer Data is affected, we will notify the relevant customer organization without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, consistent with Section 8.4 of our Terms of Service and the AssetLab Data Processing Agreement, so that they can fulfill their own notification obligations
- Notify Regulatory Authorities:Report the breach to the Office of the Privacy Commissioner of Canada (OPC) and relevant provincial authorities (including the Commission d'accès à l'information du Québec where applicable) within required timelines
- Notify End Users: Where AssetLab is the Data Controller for the affected individuals, notify those individuals consistent with applicable law
Information Provided in Breach Notifications
Our breach notifications will include:
- A description of the nature and extent of the breach, including categories and approximate number of affected individuals and data records
- The likely consequences of the breach and potential risks to affected individuals
- Measures taken or proposed to address the breach, mitigate harm, and prevent future incidents
- Contact information for our Privacy Officer and instructions for individuals to protect themselves (e.g., password resets, fraud monitoring)
- Information about your right to lodge a complaint with supervisory authorities
Incident Response Measures
Upon detecting a security incident, AssetLab will promptly:
- Contain and remediate the breach to prevent further unauthorized access
- Conduct a thorough investigation to determine the scope, cause, and impact
- Preserve evidence for forensic analysis and regulatory investigations
- Implement additional security measures to prevent recurrence
- Provide regular updates to affected individuals throughout the response process
Your Rights Following a Breach
If your personal information is affected by a data breach, you have the right to:
- Receive timely and transparent information about the breach
- Request deletion of your compromised personal information
- File a complaint with the Office of the Privacy Commissioner of Canada or relevant supervisory authority
- Seek compensation for damages resulting from the breach, subject to applicable law and our Terms of Service (Section 10: Limitation of Liability)
7. Data Retention
We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy:
- Active Accounts: Personal information and Customer Data are retained for the duration of your active subscription
- Terminated Accounts: After account termination, we retain data for 30 days to allow for reactivation or data recovery
- Production Deletion: After the 30-day retrieval period, Customer Data is deleted from production systems within 90 days, unless retention is required by law or necessary to resolve disputes
- Backup Data: Deleted data may persist in backup systems for up to 180 days following deletion from production, after which it is permanently deleted. Offsite backup archives are encrypted before upload with a key held offline, so the storage provider cannot read them at any point in their life. See Section 8.8 of the Terms of Service
- Legal Compliance: We may retain certain data longer if required by law (e.g., tax records for 7 years)
- Anonymized Data: We may retain aggregated, anonymized data indefinitely for analytics and research
8. Your Privacy Rights (PIPEDA)
Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), you have the following rights:
8.1 Right to Access
You have the right to request a copy of all personal information we hold about you. We will provide this information within 30 days of your request, subject to verification of your identity.
8.2 Right to Correction
You have the right to request corrections to any inaccurate or incomplete personal information. You can update most information directly in your account settings.
8.3 Right to Deletion
You have the right to request deletion of your personal information and Customer Data, subject to:
- Legal obligations requiring us to retain certain data
- Legitimate business purposes (e.g., fraud prevention, resolving disputes)
- Backup retention periods (up to 90 days)
Mobile app users can find step-by-step instructions on our Account & Data Deletion page.
8.4 Right to Data Portability
You have the right to export your Customer Data in commonly used formats (CSV, JSON) at any time through the Service interface.
8.5 Right to Withdraw Consent
You may withdraw your consent to our processing of your personal information at any time by terminating your account. Note that withdrawal of consent may prevent us from providing the Service.
8.6 Right to File a Complaint
If you believe we have not complied with PIPEDA, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada (OPC).
8.7 Exercising Your Rights
To exercise any of these rights, please contact us at privacy@assetlab.ca. We will respond to your request within 30 days.
9. Sensitive Personal Information We Do NOT Collect
IMPORTANT: AssetLab is NOT designed to collect, store, or process sensitive personal information. You are PROHIBITED from uploading the following types of data to the Service, as specified in our Terms of Service (Section 6.2: Prohibited Data Types).
Prohibited Data Categories
The following categories of sensitive personal information must NOT be uploaded to or stored in the Service:
- Government-Issued Identifiers: Social Insurance Numbers (SINs), Social Security Numbers (SSNs), passport numbers, driver's license numbers, national identification numbers
- Financial Account Information: Credit/debit card numbers, bank account numbers, financial credentials
- Protected Health Information (PHI): Medical records, health insurance information, diagnoses, treatment information, or any data subject to HIPAA, PHIPA, or similar health privacy laws
- Biometric Data: Fingerprints, facial recognition data, retinal scans, voiceprints, DNA, or other biometric identifiers
- Sensitive Personal Characteristics: Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, sex life, or sexual orientation
- Children's Personal Information: Personal information of individuals under age 16
- Criminal Records: Information about criminal convictions, offenses, or related security measures
- Authentication Credentials for Third-Party Systems: Passwords, API keys, access tokens, or cryptographic private keys for external systems
Consequences of Uploading Prohibited Data
If you upload prohibited sensitive data to the Service:
- You are in material breach of our Terms of Service
- AssetLab may immediately suspend or terminate your account without refund
- You are solely responsible for any regulatory penalties, fines, or third-party claims arising from such unauthorized data uploads
- You indemnify AssetLab for all costs and damages resulting from your upload of prohibited data (see Terms of Service Section 11: Indemnification)
10. Additional U.S. State Privacy Rights
If you are a resident of California or another U.S. state with applicable privacy legislation, you may have additional rights regarding your personal information. We do not sell personal information to third parties. To exercise any applicable privacy rights, please contact us at privacy@assetlab.ca.
11. Automated Decision-Making and Profiling
11.1 No Automated Decision-Making with Legal Effects
AssetLab does not engage in automated decision-making (including profiling) that produces legal effects concerning you or similarly significantly affects you.
Specifically, we do not use automated processing to make decisions about:
- Your eligibility for the Service
- Credit decisions, insurance underwriting, or similar financial assessments
- Employment decisions, performance evaluations, or disciplinary actions
- Legal rights, contractual obligations, or access to essential services
11.2 Analytics and Service Optimization
We do use automated processing for the following purposes, which do not produce legal or similarly significant effects:
- Usage Analytics: Analyzing usage patterns to improve Service performance and user experience
- Security Monitoring: Detecting fraudulent or abusive activity through automated threat detection systems
- Service Personalization: Customizing your user interface based on preferences and past activity (e.g., recently accessed assets, saved views)
- Feature Recommendations: Suggesting Service features that may be useful based on your subscription tier and usage patterns
You may opt-out of non-essential analytics and personalization through your account settings.
11.3 Artificial Intelligence and Your Data
Our position, stated precisely:
- No AssetLab-initiated transfer. AssetLab does not transmit Customer Data to any third-party artificial intelligence or machine learning provider of its own initiative, and does not use Customer Data to train any AI or machine learning model. No AI provider is an AssetLab subprocessor
- Optional AI assistant integration (MCP). Where your administrator enables this integration, records that your assistant requests are transmitted to the AI provider you have chosen, under your own account and agreement with that provider. You select, authorize, and control the connection. The integration is off by default and requires deliberate administrator action to enable. AssetLab neither receives nor retains any output of that AI provider, and is not responsible for the provider's processing of data you direct to it
- Regulated and public-sector customers. We recommend leaving the integration disabled where a statutory data-residency requirement applies, and recording in your own privacy assessment whether it is enabled and for which users
If we introduce AssetLab-operated AI features in the future (e.g., predictive maintenance recommendations, automated work order prioritization), we will:
- Clearly disclose the use of automated decision-making or profiling
- Provide information about the logic involved and the significance of such processing
- Obtain your explicit consent where required by law
- Provide mechanisms to challenge automated decisions and request human review
- Comply with all applicable AI governance frameworks and regulations
See our Terms of Service (Section 15: Artificial Intelligence Features) for additional information about AI-related terms.
12. Marketing Communications and Opt-Out
12.1 Types of Communications
AssetLab may send you the following types of communications:
- Transactional Communications (Cannot Opt-Out): Account notifications, password resets, billing confirmations, security alerts, Service updates required for platform functionality
- Service Announcements (Can Opt-Out): New feature releases, product updates, maintenance notifications, best practices guides
- Marketing Communications (Opt-In Required): Promotional emails, newsletters, webinar invitations, case studies, industry insights
12.2 CASL Compliance (Canada's Anti-Spam Legislation)
AssetLab complies with Canada's Anti-Spam Legislation (CASL). We will only send you commercial electronic messages (CEMs) if:
- You have provided express consent by opting in to receive marketing communications
- We have an existing business relationship with you (e.g., you are an active subscriber), and the message relates to your use of the Service
- You have inquired about the Service within the past 6 months, and the message relates to your inquiry
12.3 How to Opt-Out of Marketing Communications
You may opt-out of marketing communications at any time by:
- Clicking the "Unsubscribe" link in any marketing email
- Updating your email preferences in your account settings
- Emailing privacy@assetlab.ca with the subject line "Unsubscribe"
- Replying to any marketing email with "STOP" or "UNSUBSCRIBE"
We will process your opt-out request within 10 business days as required by CASL. Note that opting out of marketing communications will not affect transactional communications necessary for Service operation.
12.4 Do Not Track Signals
Some web browsers have a "Do Not Track" (DNT) feature that signals to websites that you do not want to have your online activity tracked. Currently, there is no universally accepted standard for how to respond to DNT signals. As a result, AssetLab does not respond to DNT browser signals. However, you can manage cookies and tracking through your browser settings and our cookie preferences center.
13. Data Location and Cross-Border Transfers
13.1 Primary Data Residency
Customer Data - asset records, work orders, work requests, compliance records, projects, vendors, custom fields, attachments, and audit logs - is hosted in Canada (Supabase on AWS ca-central-1, Montreal, Quebec), together with its backups. The AssetLab platform's mirror of identity fields (Clerk user ID, name, business email, role) is also stored in Canada.
We do not represent that data of every category resides in Canada. Specifically:
- Identity and authentication data is processed by Clerk in the United States
- Transactional email transits Resend in the United States, as does inbound message content where you enable the optional email intake channel
- Application error diagnostics are processed by Sentry in the United States
- Application traffic traverses Cloudflare's global edge network, where TLS is terminated for security inspection but no Customer Data is stored
Customers subject to a statutory data-residency or access-location requirement should raise it with us before entering into a contract.
13.2 Service Providers and Transfer Safeguards
Where a service provider processes data outside Canada:
- We put contractual safeguards in place equivalent to the requirements of PIPEDA and Quebec Law 25, and, for transfers in scope of the GDPR or UK GDPR, the EU Standard Contractual Clauses and the UK International Data Transfer Addendum
- We select service providers with strong security practices and recognized certifications (SOC 2 Type II at minimum, except where noted in the published Sub-processor List)
- We maintain a written Transfer Impact Assessment for each service provider outside Canada, available to customers on request under confidentiality
- Data processing is limited to what is necessary to provide the Service
13.3 Marketing Website
The public marketing site at www.assetlab.ca is hosted separately from the application and does not process Customer Data. The marketing-site hosting provider is therefore not a subprocessor under this Policy.
14. Cookies and Tracking Technologies
We use cookies and similar technologies to provide, secure, and improve the Service:
14.1 Essential Cookies
Required for the Service to function (authentication, session management, security). These cannot be disabled.
14.2 Functional Cookies
Remember your preferences and settings to enhance your experience.
14.3 Analytics Cookies
Help us understand how users interact with the Service to improve functionality and performance. These are optional and can be disabled in your browser settings.
15. Children's Privacy
The Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@assetlab.ca and we will delete the information.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
- Posting the updated Privacy Policy on our website with a new "Last Updated" date
- Sending an email notification to your registered email address
- Displaying an in-app notification upon your next login
Material changes will be effective 30 days after notice is provided. Your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy.
17. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
AssetLab CMMS Software Inc.
Privacy Officer: privacy@assetlab.ca
General Inquiries: support@assetlab.ca
Address: North Vancouver, British Columbia, Canada
Response Time: We will respond to privacy requests within 30 days
Office of the Privacy Commissioner of Canada
We encourage you to contact our Privacy Officer first so we can address your concerns before you contact the Office of the Privacy Commissioner of Canada.
If you are not satisfied with our response to your privacy concerns, you may contact the Office of the Privacy Commissioner of Canada:
Legal Notice: This Privacy Policy was last updated on August 7, 2026 (Version 3.5). We strongly recommend printing or saving a copy of this Policy for your records.
Key Changes in Version 3.5:
- Stated in Section 13.1 which categories of data are hosted in Canada and which are not - Customer Data and its backups are, while identity, transactional and intake email, error diagnostics, and edge traffic are processed in the United States
- Set the backup retention period in Section 7 to 180 days following deletion from production, matching Section 8.8 of the Terms of Service, and added the 90-day production deletion step
- Set the breach-notification timeline in Section 6.4 to notice without undue delay and, where feasible, within 72 hours, matching Section 8.4 of the Terms of Service
- Described in Section 5.1 what each subprocessor receives, including the identity mirror held in Canada and the inbound message content Resend receives where the optional email intake channel is enabled
- Replaced Section 11.3 with AssetLab's current position on artificial intelligence: Customer Data is not transmitted to any AI provider on AssetLab's initiative and is not used to train any model, and the optional AI assistant integration is off by default and connects to a provider you choose
- Added transfer safeguards to Section 13.2 (Standard Contractual Clauses, UK Addendum, and Transfer Impact Assessments available on request) and Section 13.3 on the marketing website
- Stated that third-party tools you connect yourself via API, MCP, or webhook are not AssetLab subprocessors
- Removed Apple from the subprocessor list in Section 5.1. Push notifications and voice dictation use services built into your device operating system; the disclosure remains in Sections 2.5 and 5.1
Earlier Changes (Version 3.4):
- Added Sentry (Functional Software, Inc., United States) to the subprocessor list for application error monitoring and system diagnostics, and described the narrow set of diagnostic data it receives
- Added Amazon Web Services to the subprocessor list for offsite backup storage in Canada, and noted that every archive is encrypted before upload with a key AWS does not hold
- Named Sentry in Section 13.2 as a service provider that processes data outside Canada
Earlier Changes (Version 3.3):
- Extended Section 2.5 to the native Android application, which likewise contains no analytics SDK and does not collect Usage Data, cookies, or similar tracking technologies
- Documented voice dictation on both platforms: transcription uses the speech recognition built into the device operating system, transient via Apple on iOS and on-device on Android, with no audio or voiceprint stored by AssetLab
- Scoped the Apple Push Notification service disclosure to iOS, where push notifications are currently offered
Earlier Changes (Version 3.2):
- Added Section 2.5 (Mobile Application) clarifying that the iOS app contains no analytics SDK and does not collect Usage Data or cookies
- Documented iOS camera, microphone/speech recognition, and push notification usage
- Added Apple to the subprocessor list (push notifications and speech-to-text)
Earlier Changes (Version 3.1):
- Removed Stripe payment processor references (no payment processor currently in use)
- Added Vercel and Cloudflare to subprocessor list
- Updated prohibited data types language
Previous version: Version 2.0 (October 25, 2025)
Your Privacy Matters: We are committed to transparency, accountability, and user control in all our privacy practices. If you have any questions or concerns about how we handle your personal information, please don't hesitate to contact our Privacy Officer at privacy@assetlab.ca.